Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 440772

Summary: dev-db/phpmyadmin : Obtaining current phpMyAdmin version from non SSL site is prone to MITM attack
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: a3li, web-apps
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2012-11-01 16:12:35 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=870012 :

Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5368 to the following 
vulnerability:

phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to 
phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site 
scripting (XSS) attacks by modifying this code.

References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5368
[2] http://www.phpmyadmin.net/home_page/security/PMASA-2012-7.php
[3] https://github.com/phpmyadmin/phpmyadmin/commit/50edafc0884aa15d0a1aa178089ac6a1ad2eb18a
[4] https://github.com/phpmyadmin/phpmyadmin/commit/a547f3d3e2cf36c6a904fa3e053fd8bddd3fbbb0
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-11-10 19:55:36 UTC

*** This bug has been marked as a duplicate of bug 438804 ***